Isaca
CRISC · Question #310
An organization's Internet-facing server was successfully attacked because the server did not have the latest security patches. The risk associated with poor patch management had been documented in th
Sign in or unlock CRISC to reveal the answer and full explanation for question #310. The question stem and answer options stay visible for context.
Submitted by kim_seoul· Apr 18, 2026Governance
Question
An organization's Internet-facing server was successfully attacked because the server did not have the latest security patches. The risk associated with poor patch management had been documented in the risk register and accepted. Who should be accountable for any related losses to the organization?
Options
- ARisk owner
- BIT risk manager
- CServer administrator
- DRisk practitioner
Unlock CRISC to see the answer
You've previewed enough free CRISC questions. Unlock CRISC for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.
Topics
#Risk ownership#Accountability#Risk acceptance#Risk management roles